Sub-processors
Last Updated:
Subprocessors, AI Data Use & Data Residency
Feather Financial Inc. ("Feather") uses a limited number of trusted subprocessors to help provide, maintain, and support our AI-based voice and text agents for the lending industry. We are committed to transparency and accountability in how we process data, including disclosing the third parties we work with, how AI models handle data, and where that data is stored and processed.
Jurisdiction and GDPR Applicability
Feather Financial Inc. is a U.S.-based company, and our services are currently offered only within the United States. We do not target, market to, or process personal data of individuals located in the European Union (EU) or European Economic Area (EEA).
As such, the General Data Protection Regulation (GDPR) does not apply to our operations at this time. However, we are committed to strong data protection practices and follow industry standards for privacy, security, and transparency. Should Feather begin offering services to EU-based individuals or organizations in the future, we will revise our data protection policies and this page accordingly.
Current Subprocessors
To ensure the highest level of service and security, Feather partners with subprocessors that have demonstrated robust data protection measures. Below is a list of our current subprocessors, the data each may process, and whether that data is used to train any models.
Subprocessor | Purpose | Data accessed | Location | Used to train models? |
|---|---|---|---|---|
Amazon Web Services, Inc. | Cloud infrastructure and hosting | Platform data at rest (recordings, transcripts, logs) | United States | No |
Porter Technologies Inc. | Deployment and infrastructure management | Deployment and infrastructure metadata | United States | No |
DeploySentinel, Inc. (dba HyperDX) | Logging, observability, and monitoring | Operational logs and telemetry | United States | No |
Twilio Inc. | Telephony services and voice calling | Call audio in transit, phone numbers, SMS content | United States | No |
OpenAI OpCo, LLC | AI-powered conversation models | Conversation text (transcripts, prompts) and context | United States | No |
Deepgram, Inc. | Speech-to-text and voice transcription | Call audio for transcription | United States | No |
Eleven Labs Inc. | Voice and call intelligence functionality | Text for synthesis and generated audio | United States | No |
LiveKit Inc. | Web and telephony real-time communication | Real-time audio/media streams | United States | No |
All customer data processed by Feather and its subprocessors is stored and handled exclusively within the United States.
AI Model Training and Data Use
Feather does not build or train its own foundation models, and we do not use your data, or your customers' and their consumers' data, to train, fine-tune, or improve any AI model. Customer content is used only to provide the contracted service.
We hold enterprise agreements with each of our AI subprocessors and have configured them to exclude customer data from model training:
OpenAI provides our conversational AI models. Data submitted through the OpenAI API is not used to train or improve OpenAI's models, and we have not opted into any data-sharing program. API content is retained only briefly for abuse monitoring (up to 30 days) and then deleted.
Deepgram provides speech-to-text transcription. We have opted out of Deepgram's Model Improvement Program, so call audio we send is not stored or used for model training.
Eleven Labs provides voice synthesis and call intelligence. Under our enterprise configuration, customer content is not used to train Eleven Labs' models, and we use their data-minimization controls for sensitive workflows.
None of our subprocessors use customer or consumer data to build advertising or marketing profiles, and none redistribute that data to other third parties for their own purposes.
Data Security Within Our Platform and AI Models
We apply administrative, technical, and physical safeguards across our platform and the AI components within it:
Encryption. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including call recordings, transcripts, and logs.
Access control. Access to customer and consumer data is role-based and limited to authorized personnel under least-privilege principles, and is reviewed periodically.
No persistence in models. Because customer data is excluded from training and fine-tuning, no customer or consumer content is retained in any model's weights. AI subprocessors process content transiently to return a result and then delete it per the retention terms above.
Retention and deletion. Feather retains recordings, transcripts, and logs only as long as needed to provide the service and meet applicable requirements (90 day), after which they are deleted or de-identified.
Monitoring and incident response. We log key events to support quality assurance, dispute resolution, and security, and maintain an incident-response process that allows us to contain issues and notify affected customers.
Data Residency and U.S. Data Sovereignty
All customer and consumer data processed through Feather is stored and processed within the United States.
Our cloud infrastructure (Amazon Web Services) is configured to U.S. regions, and our deployment, observability, and telephony subprocessors operate within the United States.
Our AI subprocessors process data on U.S.-based infrastructure under our enterprise agreements, including, where applicable, data-residency and zero-retention configurations that keep processing within the United States.
We do not transfer customer or consumer data outside the United States. If this ever changes, we will update this page and notify affected customers in advance.
Third- and Fourth-Party Vendors
We recognize that our customers, and their lender partners, increasingly need visibility into not just the vendors we use, but the vendors our vendors rely on. Each subprocessor listed above maintains its own subprocessors and is selected and contracted to meet our standards for U.S. data residency, confidentiality, and exclusion of customer data from model training. As part of our vendor management process, we assess our subprocessors' compliance posture and require them to uphold these standards across their own supply chain.
Subprocessor Change Notifications
We are committed to notifying our paying customers of any material changes to the subprocessors that may affect how their data is processed. These notifications are sent via email and apply only to changes relevant to the customer's use of Feather services.
Subprocessor Security and Confidentiality Requirements
Each subprocessor Feather engages is required to meet our standards for data protection, confidentiality, and security. We ensure subprocessors:
Only access data required to perform their functions;
Are contractually bound to maintain the confidentiality and security of data; and
Have implemented appropriate technical and organizational measures to protect customer data.
Questions or Concerns?
If you have any questions or concerns about this page or our data practices, please contact us at:
Artificial Intelligence lab with a mission to build the most powerful AI tools for finance industry.
© 2025 Feather Financial Inc. All Rights Reserved.

